DarkSwordâs GitHub leak threatens to turn elite iPhone hacking into a tool for the masses
DarkSwordâs GitHub leak threatens to turn elite iPhone hacking into a tool for the masses
Leaked iOS spyware has some cybersecurity professionals raising urgent alarms about potential mass iPhone compromises, a development that pairs ominously with the recent discovery of two sophisticated iOS exploit kits.
At the same time, some other experts say Appleâs defensive features for iPhones remain elite. But several factors have created unprecedented circumstances: the public accessibility of a version of DarkSword, shortly after the discovery of the original version of DarkSword and the earlier discovery of a similar kit known as Coruna, and a growing market for iPhone exploits driven by their high value as targets.
Allan Liska, field chief information security officer at Recorded Future, said he was worried about what the leaked DarkSword version could do to âdemocratizeâ iPhone exploits.
âRight now, iPhone exploitations are among the most expensive to research/implement so they have been, largely, the realm of nation-states,â he said. âIf anyone can exploit an iPhone, suddenly something that has managed to be relatively secure now is a much bigger attack surface.â
Google, iVerify and Lookout released research last week on DarkSwordâs discovery, centered on Ukraine. Google also said it saw targeting in Saudi Arabia, Turkey and Malaysia. And that was before a version turned up on GitHub, a development TechCrunch first reported and Google and iVerify have analyzed. (The week before, iVerify and Google uncovered Coruna. Google declined to comment further for this story.)
âItâs extremely alarming that this leaked out on GitHub,â said Rocky Cole, co-founder of iVerify. âI would assume that itâs being used all around the world, and including here in the United States.â
Hundreds of millions of iPhones running iOS 18 could be vulnerable to DarkSword.
âI think that the top line issues here are pretty clear: people who have devices that are vulnerable should upgrade ASAP,â said Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation. âIt is very likely that these vulnerabilities are being used right now to exploit vulnerable devices at scale, which is unusual for Apple products.â
The propagation problem
Coruna was concerning enough for Apple that it took the rare step of backporting security updates to still older versions of iOS, Cole said. The fear, he said, was that it might be wormable â capable of spreading from one device via text message to everyone in a phoneâs contact list.
But Cole said Apple hasnât released similar security-focused updates to iOS 18, for reasons he doesnât know.
Apple has emphasized the patches it has issued, urged users to update their phones and touted Lockdown Mode as a defense against spyware.
âApple devices are designed with multiple layers of security in order to protect against a wide range of potential threats, and every day Appleâs security teams around the world work tirelessly to protect usersâ devices and data,â said Apple spokesperson Sarah OâRourke. âKeeping your software up to date is the single most important thing you can do to maintain the security of your Apple products, and devices with updated software were not at risk from these reported attacks.â
IPhonesâ widespread use makes them high-value targets, fueling a thriving market for exploits. Coruna and DarkSword are indicators of this growing demand.
âItâs time for organizations to start thinking of mobile security the way they think about desktop security, which is to say everyone knows how to secure their laptop,â Cole said. And for iPhone exploit hunting in particular, âyouâre starting to see people do it at a mass level.â Furthermore, the resale market is such that exploits that once were exclusive are no longer, and AI makes it even easier to customize them in the code, he said.
DarkSword has drawn federal attention: The Cybersecurity and Infrastructure Security Agency this week added vulnerabilities that DarkSword exploits to the list that federal agencies must patch.
The number of people still using iOS 18 is large, up to 25% of all iPhones. Cole said several factors are contributing to that, such as users being leery of iOS 26âs onboard artificial intelligence or the Liquid Glass interface.
Said Galperin: âThere are many reasons why people do not keep their devices up to date, so when I tell people âjust patch your stuffâ I think it is important to realize that there are circumstances under which this is easier said than done.â
Proven defenses despite expanding risks
Despite the concerns, Cole credited iPhone for its high security standards, in particular for its app store.
For Natalia Krapiva, senior tech-legal counsel at Access Now, a key takeaway is the worrisome proliferation of commercial spyware and cyber intrusion capabilities.
âThis is exactly what human rights activists and digital security researchers have been warning governments and companies about: In the absence of effective regulation for the industry, these exploits will get out and end up in the hands of adversaries like Russia, China, Iran, or, as in the case of DarkSword, leaked online for any criminal to use,â she said.
On the other hand, Appleâs Lockdown Mode and Memory Integrity Enforcement are top-notch defensive measures, Krapiva said. Weâve yet to see a Lockdown Mode-enabled iPhone being infected with spyware, she said.
âI think weâll keep seeing more attempts to exploit both Apple and Android devices as they improve their software and hardware security,â she said. âItâs the old cat-and-mouse game.â
Adam Boynton, senior enterprise strategy manager at Jamf, said whatâs happened with Coruna and DarkSword is evidence of Appleâs success.
âWhatâs encouraging here is that Appleâs security model works,â he said. âCoruna skips devices running the latest iOS versions and avoids those with Lockdown Mode enabled entirely. Thatâs a strong validation of the defences Apple has built.
âDarkSword reinforces the same principle,â he continued. âWhere Coruna targeted older iOS versions, DarkSword demonstrates that even relatively current releases can be targeted by determined actors. Apple moved quickly to patch the vulnerabilities involved, and devices running the latest iOS are protected.â
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.